Jobiglo

No results.

This job is no longer available

This job expired on 15/08/2026. It no longer accepts applications.

GRC Consultant – Cyber Lead (Non-OS Vulnerability Management)

Renaissance InfoSystems · Melbourne

Contract Hybrid Senior 🇬🇧 English
Qualys Tenable Snyk ISO 27001 NIST CIS GRC risk assessment vulnerability management DevSecOps SDLC security

Job description

About the role

We are looking for an experienced GRC Consultant – Cyber Lead to shape and govern non‑OS vulnerability management across enterprise applications and platforms. The role will drive risk oversight, exception handling, and treatment strategies while aligning with enterprise security standards.

Key responsibilities

  • Define and implement non‑OS vulnerability management frameworks, policies, and standards.
  • Establish governance forums, escalation paths, and decision‑making processes to ensure regulatory and audit compliance.
  • Manage remediation exceptions, risk acceptance lifecycle, and validate compensating controls.
  • Perform risk assessments for unremediated vulnerabilities and support risk‑based decision‑making.
  • Lead tooling strategy, evaluate solutions (e.g., Qualys, Tenable, Snyk) and drive automation initiatives.
  • Oversee remediation outcomes from pen‑tests, audits and promote secure‑by‑design and DevSecOps practices.
  • Collaborate with Cyber, Application, Infrastructure and Operations teams, providing risk insights to senior leadership.

Required profile

  • 8‑12+ years of experience in GRC, cyber risk, and vulnerability management.
  • Hands‑on experience with application/platform (non‑OS) vulnerabilities.
  • Strong knowledge of ISO 27001, NIST, CIS frameworks.
  • Bachelor’s degree in IT, Cybersecurity or related field.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer, FAIR (preferred).
  • Excellent stakeholder engagement and communication skills.

Required skills

  • Qualys, Tenable, Snyk (or similar vulnerability scanning tools).
  • ISO 27001, NIST, CIS framework implementation.
  • GRC processes, risk assessment and exception management.
  • Vulnerability management and remediation planning.
  • DevSecOps and SDLC security practices.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Renaissance InfoSystems.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Le contrat proposé est un Contract basé à Melbourne.

Why are you reporting this job?

Thank you for your report. We will review this job.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 3 months ago

22 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Renaissance InfoSystems

Melbourne